// 1 CRITICAL · 3 ZERO-DAY · 6 CVE · 3 EXPLOIT IN THE LAST 24H
CYBERSECCVE

CVE-2026-40400: RCE in PowerShell via Help File, Patch Available

ZDI-26-414 discloses a directory traversal flaw in PowerShell help file parsing that leads to remote code execution with user interact…

Jul 20, 2026views - 1.2k

CYBERSECCVE

Cisco ISE Authenticated Directory Traversal (CVE-2026-20146) Exposes System Files

A directory traversal flaw in Cisco Identity Services Engine lets authenticated attackers read sensitive files. The vulnerability, rat…

Jul 20, 2026views - 1.3k

CYBERSEC

Adobe Creative Cloud Update Service Turned Into Privilege Escalation Weapon

ZDI-26-419 reveals a vulnerability in AdobeUpdateService that allows local privilege escalation from low-privilege user to SYSTEM on W…

Jul 16, 2026views - 1.2k

CYBERSECCRITICAL

Synology DS925+: Pre-Auth Root RCE via Weak Redis Passwords — Patch Available

ZDI-26-423 discloses a pre-authentication vulnerability in the MailPlus Redis component of the Synology DiskStation DS925+. Reversible…

Jul 16, 2026views - 1.4k

VULNCRITICAL

NVIDIA NeMo Framework: RCE Vulnerability in ML Checkpoints

An unsafe deserialization flaw in NVIDIA NeMo Framework checkpoints enables remote code execution. User interaction is required, but t…

Jul 16, 2026views - 1.2k

VULNCRITICAL

7-Zip XZ Parser RCE Vulnerability: Opening an Archive Is Enough

A heap-based buffer overflow in 7-Zip's XZ parser enables remote code execution. The flaw, tracked as ZDI-26-444 and CVE-2026-14266, t…

Jul 16, 2026views - 1.5k

CYBERSEC

SAP Patches CVSS 9.9 ABAP Kernel Bug: Mandatory Downtime or SAP GUI for HTML Breaks

CVE-2026-44747 is an out-of-bounds write in the SAP NetWeaver ABAP kernel with total impact on confidentiality, integrity, and availab…

Jul 14, 2026views - 1.2k

CYBERSECZERO-DAY

SonicWall SMA 1000: Two Actively Exploited Zero-Days and a Patch That Isn't Enough

SonicWall patched two zero-days under active exploitation in SMA 1000 Series appliances, but the vendor mandates full re-imaging or re…

Jul 14, 2026views - 1.3k

CYBERSECZERO-DAY

FortiBleed: 75,000 Firewalls at Risk from Stolen Credentials, Not a Zero-Day

FortiBleed hits already-patched FortiGate devices: credentials stolen in prior incidents enable administrative access without exploiti…

Jul 14, 2026views - 1.4k

CYBERSEC

Security Vendor Jscrambler Becomes Supply-Chain Vector: 5 Malicious npm Versions

Threat actors compromised Jscrambler's npm publishing credentials and released five malicious versions of the jscrambler package conta…

Jul 13, 2026views - 1.3k

CYBERSECZERO-DAY

ZDI Publishes 0-Day in Glary Utilities: LPE via Junction, No Patch

Trend Micro's Zero Day Initiative has disclosed ZDI-26-402, a local privilege escalation vulnerability in Glarysoft Glary Utilities. T…

Jul 12, 2026views - 1.3k

CYBERSECCRITICAL

Zimbra Patches Critical Stored XSS in Classic Web Client, Reported by Google TAG

Zimbra released ZCS 10.1.19 on July 7, 2026 to fix a stored cross-site scripting vulnerability in the Classic Web Client reported by G…

Jul 10, 2026views - 967